Fino

Hellenic Data Protection Authority (HDPA) · 19 July 2022

DO VALUE GREECE LOANS & CREDITS CLAIM MANAGEMENT S.A.

Insufficient fulfilment of data subjects rights

Fine€20,000Fine issued
Regulator
Hellenic Data Protection Authority (HDPA)
Decided
19 July 2022
Country
Greece
Sector
Finance, Insurance and Consulting
Regulator’s reference
Not recorded
Fino case number
2022/GR/010
Export as PDF

What happened

The Greek DPA fined the National Bank of Greece €20,000 for violating Article 13 GDPR by not informing customers that the chip of their debit/credit cards collected information on the last 10 transactions. The DPA also held that the controller installed the chip without a valid legal basis and in breach of the principle of transparency.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data principles
  • Data subject rights
  • Transparency
  • Unlawful processing

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2022/GR/010.